<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not substituted certificate in browser Https Inspection in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122169#M17479</link>
    <description>&lt;P&gt;Agree cold heartedly.&lt;/P&gt;</description>
    <pubDate>Fri, 25 Jun 2021 12:12:11 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-06-25T12:12:11Z</dc:date>
    <item>
      <title>Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122021#M17440</link>
      <description>&lt;P&gt;Hello everyone!&lt;/P&gt;&lt;P&gt;I have Gaia R80.40 distributed deployment (management + clusterXL). I trying enable Https inspection the other day, created self-signed certificate, install this in "trusted root authorities" in Windows machine, but when i open any https site, certificate not substituted in browser.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="https insp enable.jpg" style="width: 528px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12303i46BD521C52AAC40B/image-dimensions/528x466?v=v2" width="528" height="466" role="button" title="https insp enable.jpg" alt="https insp enable.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cert.jpg" style="width: 579px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12304i55823A0A3E67B2A0/image-dimensions/579x537?v=v2" width="579" height="537" role="button" title="cert.jpg" alt="cert.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please tell me why this can happen?&lt;/P&gt;&lt;P&gt;With Regards, Herman&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 11:32:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122021#M17440</guid>
      <dc:creator>Herman</dc:creator>
      <dc:date>2021-06-24T11:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122026#M17441</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/64691"&gt;@Herman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;have you defined some HTTPS inspection rules ?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Bild 24.06.21 um 14.00.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12307i66D22513C29543DE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Bild 24.06.21 um 14.00.jpg" alt="Bild 24.06.21 um 14.00.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 12:01:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122026#M17441</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-06-24T12:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122029#M17443</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;only default predefined rule&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="httpsrule.jpg" style="width: 882px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12308i460224E4665AB654/image-dimensions/882x169?v=v2" width="882" height="169" role="button" title="httpsrule.jpg" alt="httpsrule.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 12:09:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122029#M17443</guid>
      <dc:creator>Herman</dc:creator>
      <dc:date>2021-06-24T12:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122049#M17447</link>
      <description>&lt;P&gt;Did you install the policy after enabling HTTPS Inspection in the FW object? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 14:35:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122049#M17447</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2021-06-24T14:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122053#M17449</link>
      <description>&lt;P&gt;I'm new in checkpoint environment &lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;, but if you mean it (see screenshot)&amp;nbsp;then yes&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2323.jpg" style="width: 549px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12314iC3D8FF4C31C70EDE/image-size/large?v=v2&amp;amp;px=999" role="button" title="2323.jpg" alt="2323.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 14:48:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122053#M17449</guid>
      <dc:creator>Herman</dc:creator>
      <dc:date>2021-06-24T14:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122069#M17457</link>
      <description>&lt;P&gt;Do you use the gateway as a proxy or transparent proxy? Is the gateway inline en route to the internet? I think the object "Internet" is based on the topology, is your topology correct (edit cluster -&amp;gt; network management -&amp;gt; the interface leading to the WAN should be marked as external) ?&lt;BR /&gt;&lt;BR /&gt;You can set your ssl inspect rule to "log" and create another rule like this below it "Source: any Destination:any Service:any Action:bypass Track:log". &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 15:36:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122069#M17457</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2021-06-24T15:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122095#M17460</link>
      <description>&lt;P&gt;No proxy not used, if i right you understand&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="proxy.jpg" style="width: 583px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12317i3A70745F99E8DDF0/image-dimensions/583x510?v=v2" width="583" height="510" role="button" title="proxy.jpg" alt="proxy.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;Yes, gateway &lt;SPAN&gt;inline en route to the internet. C&lt;/SPAN&gt;hecked Network topology, and External interface set as External zone (it's has not been mark as External zone), install policy, but it's did not affect&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="external.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12324iE63467A45EB4A5D2/image-size/large?v=v2&amp;amp;px=999" role="button" title="external.jpg" alt="external.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;Not sure that right understand, but create bypass "test rule" and enable log tracking:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bypassrule.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12322i82C3C511817950AB/image-size/large?v=v2&amp;amp;px=999" role="button" title="bypassrule.jpg" alt="bypassrule.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;And now in logs &amp;amp; monitor tab if set filter as HTTPS Inspection&amp;nbsp;may be view this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="https lpgs.jpg" style="width: 851px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12323i48C8AB18D74092EB/image-dimensions/851x359?v=v2" width="851" height="359" role="button" title="https lpgs.jpg" alt="https lpgs.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;But&amp;nbsp;unfortunately certificate not&amp;nbsp;&lt;SPAN&gt;substituted after that&lt;BR /&gt;--------&lt;BR /&gt;PS&amp;nbsp;English is not my native language, so please be kind to my mistakes )))&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 18:42:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122095#M17460</guid>
      <dc:creator>Herman</dc:creator>
      <dc:date>2021-06-24T18:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122097#M17461</link>
      <description>&lt;P&gt;You might wanna redact the public IPs next time and don't worry about your english &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Your Interface names look strange to me, do they match the names as configured on the gateway OS?&amp;nbsp; Can you switch the HTTPS Inspection rules around?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 18:29:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122097#M17461</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2021-06-24T18:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122100#M17462</link>
      <description>&lt;P&gt;This looks good. HTTPS inspection catches the traffic, but it‘s bypassed regarding your rule. Something with defining the „internet“ as destination in your second rule does work like you want. Have a look at&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/687"&gt;@Danny&lt;/a&gt;&amp;nbsp;great post &amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Management/Properly-defining-the-Internet-within-a-security-policy/m-p/10561#M17029" target="_blank" rel="noopener"&gt;Properly defining the Internet within a security policy&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can try to define another rule first with your client as source and destination any with action „inspect“ to see if this connection will be intercepted.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 18:47:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122100#M17462</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-06-24T18:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122102#M17463</link>
      <description>&lt;P&gt;In gateway OS interface have this names, they don't match with names in SmartConsole:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="interf names in os.jpg" style="width: 590px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12325iAD3C11F8B4AF9EEB/image-size/large?v=v2&amp;amp;px=999" role="button" title="interf names in os.jpg" alt="interf names in os.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;With inspections rules, i try some experiments&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 19:08:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122102#M17463</guid>
      <dc:creator>Herman</dc:creator>
      <dc:date>2021-06-24T19:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122104#M17464</link>
      <description>&lt;P&gt;I'm try to define first rule with destination any instead "Internet" for my client machine, but in logs not showing record with "inspect" action for Https inspection. Of course&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt; after create rule and install policy, tried to open some https sites in Chrome&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="test rule https 2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12326i0F6A991CDFA9F517/image-size/large?v=v2&amp;amp;px=999" role="button" title="test rule https 2.jpg" alt="test rule https 2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 19:18:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122104#M17464</guid>
      <dc:creator>Herman</dc:creator>
      <dc:date>2021-06-24T19:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122130#M17468</link>
      <description>&lt;P&gt;By the way, your last rule in the HTTPS Inspection policy should be any any bypass.&lt;BR /&gt;Without that, you very likely will have performance issues&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 22:42:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122130#M17468</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-24T22:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122137#M17472</link>
      <description>&lt;P&gt;I know this may sound like a silly question, but did you make sure that windows machine is actually going through CP firewall? If you do tcpdump -nni host x.x.x.x (with x.x.x.x as windows machine IP address), what do you see? Have you tried another machine or just one? From screenshots you pasted, config looks okay to me.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 01:46:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122137#M17472</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-06-25T01:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122147#M17474</link>
      <description>&lt;P&gt;It's another topic but to me in newer versions of the Smart Console it should be the default behaviour with a warning message if it doesn't exist, similar to the message if an inline layer is missing a cleanup rule. It doesn't make sense to have Tech Talks explaining that it's best practices to have any/any/bypass to prevent performance issues due to undefined sessions and have the system out of the box doing the exact opposite, causing issues to unsuspecting customers.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 06:02:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122147#M17474</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2021-06-25T06:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122169#M17479</link>
      <description>&lt;P&gt;Agree cold heartedly.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 12:12:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122169#M17479</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-06-25T12:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122451#M17529</link>
      <description>&lt;P&gt;Hello everyone!&lt;BR /&gt;I fixed this, just add new layer with Application &amp;amp; URL filtering blade in Access Control Policy. Than added three rules and it's work fine&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="right cert.jpg" style="width: 525px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12357i26873926CBD39399/image-dimensions/525x455?v=v2" width="525" height="455" role="button" title="right cert.jpg" alt="right cert.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="app layer.jpg" style="width: 855px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12358i83F72249E91D2948/image-dimensions/855x324?v=v2" width="855" height="324" role="button" title="app layer.jpg" alt="app layer.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 07:25:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/122451#M17529</guid>
      <dc:creator>Herman</dc:creator>
      <dc:date>2021-06-29T07:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/219844#M42036</link>
      <description>&lt;P&gt;I have tried all of this stuff but I still cannot figure out by the https inspection is not inspecting. it shows bypassing logs but no inspection logs&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jul 2024 15:58:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/219844#M42036</guid>
      <dc:creator>Simo-94</dc:creator>
      <dc:date>2024-07-06T15:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/219845#M42037</link>
      <description>&lt;P&gt;See if my post below helps, if not, we can do remote. I have perfectly working ssl inspection lab.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Https-inspection-tip/m-p/219139" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Https-inspection-tip/m-p/219139&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jul 2024 16:05:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/219845#M42037</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-06T16:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/219855#M42038</link>
      <description>&lt;P&gt;hi Andy, Thank you very much for you help. yes a remote session would be very helpful. here is what I did to configure https inspection and let me know if there something that I missed :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried in my lab it does not seem to "inspect" traffic. when I set the https policy to inspect I do not see any logs of inspection but when I set it to bypass I see the logs of bypassing.&lt;/P&gt;&lt;P&gt;1. I enbaled application and url filtering blade&lt;BR /&gt;2. enabled https inspection. created the certificate and exported it and isntalled it on the client machine. I checked the browser certificate repository to make sure taht the certificate was installed and it was.&lt;BR /&gt;3. enabled the application and url filtering on the access policy&lt;BR /&gt;4. set the https policy to any any inspect and log&lt;BR /&gt;5. installed access policy&lt;/P&gt;&lt;P&gt;when I visit https website and I try to check the logs to see the inspection, I don't see anything. and on the browser when I click to which certificate is being used I don't see the one that I created.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jul 2024 14:53:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/219855#M42038</guid>
      <dc:creator>Simo-94</dc:creator>
      <dc:date>2024-07-07T14:53:17Z</dc:date>
    </item>
    <item>
      <title>Re: Not substituted certificate in browser Https Inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/219856#M42039</link>
      <description>&lt;P&gt;Just came back from long bike ride, saw your update &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Anyway, since Im on call with work for this and next weekend, I usually do some labs on Sundays anyway, so let me know, happy to do remote and help you.&lt;/P&gt;
&lt;P&gt;Just message me directly, we can do zoom. I have my private gmail one, as my company uses teams, but its good for 40 mins and if we need another one, we just wait 10 mins and "fire up" next session.&lt;/P&gt;
&lt;P&gt;Let me know.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jul 2024 14:55:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-substituted-certificate-in-browser-Https-Inspection/m-p/219856#M42039</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-07T14:55:51Z</dc:date>
    </item>
  </channel>
</rss>

